Next blog post:
Everything SMTP. Get the mail goodness here:
LuemmelSec - Blog
In this blog-post I am trying to demystify SMTP (at least for myself). What exactly is it used for? What parties are involved? What about authentication and when? What attack surfaces are you opening with incorrect settings? As you may have read in the other posts, I will most likely try to reflect my knowledge on specific topics or work on certain problems I face (mainly during work), where these blog-posts are aimed to help me. This time it´s all about SMTP in regards of possible attacks and countermeasures, all from the point of view of an external attacker.
